Umbra Wiki technique technique/T1213.001
Back to wiki

T1213.001 — Confluence

provenance: imported · ATT&CK: T1213.001

T1213.001: Confluence

MITRE ATT&CK® Enterprise technique

Tactics Collection
Platforms SaaS
Permissions required
Version 1.1
Parent technique T1213

Description

Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as:

  • Policies, procedures, and standards
  • Physical / logical network diagrams
  • System architecture diagrams
  • Technical system documentation
  • Testing / development credentials (i.e., Unsecured Credentials)
  • Work / project schedules
  • Source code snippets
  • Links to network shares and other internal resources

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1213/001
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/